Vulnerability Description
Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through various parameters. Attackers can craft malicious requests with SQL payloads to extract sensitive database information including user credentials and system data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netartmedia | Php Mall | 4.1 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/46562ExploitVDB Entry
- https://www.vulncheck.com/advisories/netartmedia-php-mall-multiple-sql-injectionThird Party Advisory
FAQ
What is CVE-2019-25540?
CVE-2019-25540 is a vulnerability with a CVSS score of 8.2 (HIGH). Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through various parameters. Attackers...
How severe is CVE-2019-25540?
CVE-2019-25540 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25540?
Check the references section above for vendor advisories and patch information. Affected products include: Netartmedia Php Mall.